Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks

Summary

Cisco has confirmed a critical authentication bypass vulnerability (CVE-2026-20079) in its Secure Firewall Management Center (FMC) software is being actively exploited in attacks. This flaw allows attackers to bypass authentication mechanisms.

IFF Assessment

FOE

The active exploitation of a critical vulnerability by attackers poses a direct threat to organizations, making it bad news for defenders.

Severity

10.0 Critical

CISA KEV: Listed as actively exploited. Federal patch due: September 12, 2026. Known ransomware use: Unknown.

Defender Context

This confirmed exploitation of a high-severity vulnerability in a widely used network management tool highlights the urgent need for organizations to prioritize patching and implementing robust network security monitoring. Defenders should be vigilant for any signs of unauthorized access to their Cisco FMC environments.

Read Full Story →